Saved in:
Bibliographic Details
Main Authors: Rosenthal, Jonathan, Liang, Shanchao, Zhang, Kevin, Tan, Lin
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2409.10643
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929501342007296
author Rosenthal, Jonathan
Liang, Shanchao
Zhang, Kevin
Tan, Lin
author_facet Rosenthal, Jonathan
Liang, Shanchao
Zhang, Kevin
Tan, Lin
contents Machine Learning as a Service (MLaaS) is often provided as a pay-per-query, black-box system to clients. Such a black-box approach not only hinders open replication, validation, and interpretation of model results, but also makes it harder for white-hat researchers to identify vulnerabilities in the MLaaS systems. Model extraction is a promising technique to address these challenges by reverse-engineering black-box models. Since training data is typically unavailable for MLaaS models, this paper focuses on the realistic version of it: data-free model extraction. We propose a data-free model extraction approach, CaBaGe, to achieve higher model extraction accuracy with a small number of queries. Our innovations include (1) a novel experience replay for focusing on difficult training samples; (2) an ensemble of generators for steadily producing diverse synthetic data; and (3) a selective filtering process for querying the victim model with harder, more balanced samples. In addition, we create a more realistic setting, for the first time, where the attacker has no knowledge of the number of classes in the victim training data, and create a solution to learn the number of classes on the fly. Our evaluation shows that CaBaGe outperforms existing techniques on seven datasets -- MNIST, FMNIST, SVHN, CIFAR-10, CIFAR-100, ImageNet-subset, and Tiny ImageNet -- with an accuracy improvement of the extracted models by up to 43.13%. Furthermore, the number of queries required to extract a clone model matching the final accuracy of prior work is reduced by up to 75.7%.
format Preprint
id arxiv_https___arxiv_org_abs_2409_10643
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle CaBaGe: Data-Free Model Extraction using ClAss BAlanced Generator Ensemble
Rosenthal, Jonathan
Liang, Shanchao
Zhang, Kevin
Tan, Lin
Cryptography and Security
Machine Learning
Machine Learning as a Service (MLaaS) is often provided as a pay-per-query, black-box system to clients. Such a black-box approach not only hinders open replication, validation, and interpretation of model results, but also makes it harder for white-hat researchers to identify vulnerabilities in the MLaaS systems. Model extraction is a promising technique to address these challenges by reverse-engineering black-box models. Since training data is typically unavailable for MLaaS models, this paper focuses on the realistic version of it: data-free model extraction. We propose a data-free model extraction approach, CaBaGe, to achieve higher model extraction accuracy with a small number of queries. Our innovations include (1) a novel experience replay for focusing on difficult training samples; (2) an ensemble of generators for steadily producing diverse synthetic data; and (3) a selective filtering process for querying the victim model with harder, more balanced samples. In addition, we create a more realistic setting, for the first time, where the attacker has no knowledge of the number of classes in the victim training data, and create a solution to learn the number of classes on the fly. Our evaluation shows that CaBaGe outperforms existing techniques on seven datasets -- MNIST, FMNIST, SVHN, CIFAR-10, CIFAR-100, ImageNet-subset, and Tiny ImageNet -- with an accuracy improvement of the extracted models by up to 43.13%. Furthermore, the number of queries required to extract a clone model matching the final accuracy of prior work is reduced by up to 75.7%.
title CaBaGe: Data-Free Model Extraction using ClAss BAlanced Generator Ensemble
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2409.10643